Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.20.0-1
1.23.1-1ubuntu1
1.23.1-1ubuntu4
1.23.1-1ubuntu4+esm1
Ecosystem specific
{
"binaries": [
{
"binary_name": "php-twig",
"binary_version": "1.23.1-1ubuntu4+esm1"
}
],
"priority_reason": "It's exploited only if an user creates a vulnerable template"
}
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.24.0-2ubuntu1
2.*
2.4.4-2ubuntu1
2.4.6-1
2.4.6-1ubuntu0.1~esm1
Ecosystem specific
{
"binaries": [
{
"binary_name": "php-twig",
"binary_version": "2.4.6-1ubuntu0.1~esm1"
}
],
"priority_reason": "It's exploited only if an user creates a vulnerable template"
}